CVE-2009-2698

Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 27 Aug 2009, 17:00
Last modified:07 Aug 2024, 05:59

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
26.12% HIGH
26% probability +3.06%
KEV
Not listed
Ransomware
No reports
Public exploits
4 found
Dark Web
Not detected

Timeline

27 Aug 2009, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 05:59
Last Modified
Vulnerability information updated

Description

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 26.12% Percentile: 96%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 8.04 | 8.10 | 9.04

  • fedoraprojectfedora

    10

  • linuxlinux_kernel

    < 2.6.19

  • redhatenterprise_linux_desktop

    4.0 | 5.0

  • redhatenterprise_linux_eus

    4.8 | 5.3

  • redhatenterprise_linux_server

    4.0 | 5.0

  • redhatenterprise_linux_server_aus

    5.3

  • redhatenterprise_linux_workstation

    4.0 | 5.0

  • suselinux_enterprise_desktop

    10:sp2

  • suselinux_enterprise_server

    9 | 10:sp2

  • UnknownESXi

    4.0

  • UnknownvCenter Server

    4.0

References (26)